Atlas / MCP servers / digitalocean / DigitalOcean

DigitalOceanSAFE

mcp/digitalocean/digitalocean-1

DigitalOcean MCP Server for deploying and managing apps on App Platform

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
30 22r · 7w · 1d
Transport
stdio
License
—
Stars
80
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚠️ ARCHIVE NOTICE This repository has been archived. Please use [@digitalocean-labs/mcp-digitalocean](https://github.com/digitalocean-labs/mcp-digitalocean/)

[](https://www.npmjs.com/package/@digitalocean/mcp) [](LICENSE)

This MCP server exposes DigitalOcean App Platform functionality through standardized tools that can be used by any MCP client, including Claude Desktop and Cursor. It enables AI assistants to directly manage your DigitalOcean apps without writing code or memorizing API endpoints.

[](https://cursor.com/install-mcp?name=digitalocean&config=eyJjb21tYW5kIjoibnB4IEBkaWdpdGFsb2NlYW4vbWNwIiwiZW52Ijp7IkRJR0lUQUxPQ0VBTl9BUElfVE9LRU4iOiJZT1VSX0RPX1RPS0VOIn19)

📚 Table of Contents

  • 🚀 What Can You Do With It?
  • 🧰 Prerequisites
  • ⚙️ Setting up your DigitalOcean MCP Server
  • Generate Your API Token
  • Add the Server to Your MCP Client
  • Claude Desktop
  • Cursor
  • Windsurf Setup
  • 💬 Example Prompts
  • 🛠 Available Tools
  • 🧯 Troubleshooting
  • 🤝 Contributing
  • 📄 License

🚀 What Can You Do With It?

You can now do things like:

  • Deploy a new app from a GitHub repo
  • Quickly redeploy an existing app with the latest changes
  • See logs, restart components, or delete old environments
  • Check available regions and create apps based on what’s supported
  • Build and deploy an app from scratch, entirely
Read from source at commit bda7a2dab9baOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp --env DIGITALOCEAN_API_TOKEN=${DIGITALOCEAN_API_TOKEN} -- npx -y @digitalocean/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@digitalocean/[email protected]"
      ],
      "env": {
        "DIGITALOCEAN_API_TOKEN": "${DIGITALOCEAN_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (30)

22 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cancel_deploymentreadCancel a deployment by ID
commit_app_rollbackwriteCommit an app rollback. This action permanently applies the rollback and unpins the app to resume new deployments.
create_appwriteCreate a new app by submitting an app specification. For documentation on app specifications (
create_database_clusterwriteCreate a new database cluster.
create_deploymentwriteCreate a new deployment for an app
delete_appdestructiveDelete an app by ID
download_logsreadGive the URL of the logs, download the logs and return them as a string.
get_appreadGet an app by ID
get_database_clusterreadGet information about a specific database cluster.
get_database_cluster_certificatereadGet the certificate for a specific database cluster.
get_database_optionsreadGet a list of all database options available for creating a database cluster. This includes available regions, versions, and sizes for each database engine.
get_deploymentreadGet a deployment by ID
get_deployment_logs_urlreadGets the URL of the logs for a deployment. Before fetching the logs, you need to get the URL of the logs.
get_instance_size_by_slugreadRetrieve information about a specific instance size slug for
list_app_alertsreadList alerts associated to the app and any components. This includes configuration information about the alerts including emails, slack webhooks, and triggering events or conditions.
list_app_regionsreadList all regions supported by App Platform.
list_appsreadList all apps on your account. Information about the current active deployment as well as any in progress ones will also be included for each app.
list_database_cluster_databasesreadList all databases for a specific database cluster.
list_database_cluster_usersreadList all users for a specific database cluster.
list_database_connection_poolsreadList all connection pools for a specific database cluster.
list_database_firewall_rulesreadList all firewall (trusted sources) rules for a specific database cluster.
list_database_topicsreadList all topics for a specific database kafka cluster.
list_databases_clusterreadList all database clusters in your account. This includes information about each cluster
list_deploymentsreadList all deployments for an app
list_instance_sizesreadList all instance sizes for
revert_app_rollbackreadRevert an app rollback. This action reverts the active rollback by creating a new deployment from the latest app spec prior to the rollback and unpins the app to resume new deployments.
update_appwriteUpdate an existing app by submitting a new app specification. For documentation on app specifications (
update_app_alert_destinationswriteUpdate alert destinations for an app
update_database_firewall_ruleswriteUpdate the firewall (trusted sources) rules for a specific database cluster.
validate_app_specreadPropose and validate a spec for a new or existing app. The request returns some information about the proposed app, including app cost and upgrade cost. If an existing app ID is specified, the app spec is treated as a proposed update to the existing app.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_app
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, zod, @types/node, js-yaml, typed-openapi, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
src/specs/digitalocean-openapi.yaml
src/specs/digitalocean-openapi.yaml
Why it matters. 2073985 bytes not read

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha bda7a2dab9bafull audit observations/trust-audit/mcp-server/digitalocean__digitalocean-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07bda7a2dab9baSAFEB89first audit
06

Questions

What is the DigitalOcean MCP server?

DigitalOcean MCP Server for deploying and managing apps on App Platform

What tools does DigitalOcean expose?

30 in total: 22 read-only, 7 that write, and 1 that can delete or overwrite (delete_app). Every one is listed on this page with its risk.

Is DigitalOcean safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does DigitalOcean need?

It reads DIGITALOCEAN_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does DigitalOcean run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @digitalocean/mcp at 0.0.13.

How current is this page?

The grade is for one exact copy of the source (bda7a2dab9ba), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement